Skip to main content
PRIVACY NOTICE

Your project details are for your proposal—not a mailing list.

This notice describes how outcomeguild.com uses a short project brief to prepare an automated preliminary proposal, send the result and support a later project discussion.

Who is responsible

The Outcome Guild is an independent software delivery consulting practice led by Oleksii Sytar. For privacy questions, access requests, or deletion requests, email oleksii.sytar@gmail.com.

What is collected

The project brief collects your name, email, optional company, the software or process you want to build or improve, any project details you supply, and consent choices. Details may include an existing prototype, intended users, desired features, timing, budget or constraints. Sanitized campaign attribution may be attached to the enquiry when you allow measurement. The service creates saved input and evaluation records, internal lead-quality assessments, a preliminary proposal and PDF when the brief can be processed safely, and processing and delivery records. Basic security logs may include request time, browser information, and a short-lived, one-way identifier used to limit automated submissions.

Your draft, recordings and AI assistance

You can describe an idea without creating an account. Text, available recording parts, attachments and your current step are saved in this browser’s IndexedDB when storage permits. “Saved on this device” is shown only after the storage transaction completes. Browser storage can be cleared or evicted; download important text and recordings, or explicitly sync a private draft before switching devices.

Recording asks for microphone permission only after you choose to speak. The site reads audio levels locally to help detect silence. It pauses when the page becomes hidden where browser support permits; browser or phone interruptions may prevent the last unsaved part from being recovered. You can listen to saved audio, download it, remove it, retry transcription or use text instead. We accept up to three audio, PDF or plain-text attachments of 3 MB each.

Choosing private sync, AI assistance, an emailed resume link or final submission sends the necessary draft content and attachments to private Supabase storage. OpenAI receives the text you ask it to understand or the selected attachment you ask it to transcribe or read. The editable summary does not replace your original. These actions do not subscribe you to marketing or begin development. A private draft and its attachments expire 30 days after first sync and are removed by the retention job. The access link is a bearer capability: anyone holding it can open that draft. It is not included in analytics and is removed from the visible URL after recovery begins.

You can delete the draft and attachments from its workspace. This removes the current device copy and its private server draft, not copies downloaded, emailed or restored onto another device. Deleting a draft does not withdraw or erase a separately submitted enquiry; use the privacy contact above for deletion of those records. A final submission also keeps a retry-safe copy of the accepted contact details and request on this device until you delete it or browser storage is cleared.

An emailed resume link is an essential message you request through Brevo. It opens the latest privately synced draft; later device-only changes are not available on another device until synced. Requested resume-link emails are not used for recipient-level open or click measurement.

Why your request is used

The information is used to prepare and send a preliminary project proposal, identify assumptions or missing details, protect the service from abuse, operate quality checks, and contact you directly about that project. Internal lead-quality assessment helps prioritize follow-up and, with the necessary consent, measure advertising results. It does not require you to prove buying readiness or have an approved minimum budget before receiving a preliminary proposal. The form does not add you to a general marketing mailing list.

AI-assisted evaluation

OpenAI models help interpret the project description, identify assumptions and risks, check the proposed work and describe how the software would work. Contact fields are kept out of the model-facing brief, and the estimate is calculated independently of a selected budget. Internal lead-quality analysis is separate from preparing the customer result. A preliminary proposal does not wait for Oleksii to approve the enquiry.

AI output uses structured formats and is checked by application and database rules. Spam, unsafe content, unusable information or a processing failure may prevent an automatic result. A proposal remains preliminary and advisory: it does not create a contract, fixed quote, warranty, or delivery commitment. Final scope, price and terms require a separate written agreement.

Service providers

Vercel provides web hosting and the durable workflow that coordinates proposal preparation. Supabase provides the private database and private storage for briefs, evaluation records, generated proposal assets, and PDFs. OpenAI processes selected project details for the AI-assisted evaluation. Brevo provides contact synchronization, transactional proposal email, and booking. Upstash holds short-lived abuse-prevention counters. Google Analytics and PostHog provide optional website and funnel measurement, and Google Ads Data Manager can receive the limited qualified-opportunity conversion described below. These providers process data to operate the service under their own contractual, privacy, and security terms.

Brevo receives your contact details, sanitized attribution, internal lead-quality and processing states, the requested email content, and an encrypted active-window mirror of the accepted raw and normalized brief. The brief mirror is encrypted before it leaves the application; Brevo receives ciphertext plus opaque identifiers and integrity hashes, while the random per-enquiry decryption key remains in the private Supabase database. This keeps the enquiry operational if a later worker fails without placing readable free-text brief data into Brevo's indefinitely retained custom-event log. Brevo sends the transactional result email, including a private proposal link when a proposal is ready. Brevo reports delivery, deferral, and bounce events back to the service. If you separately select optional email measurement, Brevo may also report recipient-level opens and requested-email link clicks. Open pixels may be affected by privacy features and links by security scanners, so those signals are directional rather than proof of human intent.

Without optional email-measurement consent, we instruct Brevo not to identify you in open and click measurement. Brevo may still include a measurement pixel and redirect links to produce anonymous aggregate statistics; opting out does not remove those elements from the email. These anonymous statistics are not used to score your enquiry. Delivery and bounce records remain necessary to send the proposal you requested.

Supabase is the canonical source for the submitted brief, consent and attribution snapshots, evaluation and internal lead-quality revisions, review audits, proposal and commercial events, provider outboxes, and email-delivery records. Private proposal assets are served through the application from server-only storage rather than a public bucket. Brevo, analytics, and advertising systems are downstream operational projections and cannot alter the saved evaluation.

Optional website measurement and session replay

Google Analytics and PostHog load only after you select “Allow measurement.” If you select “Essential only,” neither measurement runtime is loaded and no Google Ads qualified-opportunity export is eligible. When enabled, the measurement providers can receive the sanitized public page viewed, query-free referring source, approximate location, browser and device category, and explicit funnel events such as opening the estimator, progressing through a step, completing a brief, viewing a proposal, downloading its PDF, or selecting a booking link. These records show observed actions and technical context; they do not establish why a visitor acted. Selecting a booking link is a microconversion event and does not mean an appointment was completed.

PostHog session replay is limited to consented public acquisition and editorial pages. It is disabled on thank-you pages, every private proposal page, and API routes. All form inputs are masked and estimator text is masked before replay data leaves the browser. Console contents, request or response bodies, request headers, and private proposal content are not recorded. The private proposal token is replaced with /proposal/private in event URLs, and the corresponding API path is similarly redacted.

When “Allow measurement” is selected, only utm_source, utm_medium, utm_campaign, utm_id, utm_term, utm_content, gclid, gbraid, wbraid, gad_source, fbclid, ttclid, msclkid, and li_fat_id may be retained from the landing URL for campaign attribution. If you then submit a brief, that sanitized attribution is attached to the enquiry in Supabase and Brevo. Other query parameters are removed. If you choose “Essential only,” the website does not persist or attach this campaign-attribution record.

Your name, email address, company, free-text answers, questionnaire selections, proposal content, and private access keys are never sent to Google Analytics or PostHog. After a successful submission with measurement consent, PostHog may use a random browser identifier to connect that browser's activity and later consented submissions. A separate random eight-character public brief identifier records which enquiry an event relates to; email is not the analytics identity. Receiving a proposal does not by itself make the enquiry a Google Ads qualified_opportunity. That signal requires the internal lead-quality rules, a genuine non-test, non-internal, non-spam enquiry, the necessary measurement consent, and a supported Google click identifier. Google receives only the selected downstream event and required attribution—not the questionnaire or proposal. Consent absence is never treated as negative lead-quality evidence and does not prevent a requested proposal. Advertising storage, Google signals, and advertising personalization remain disabled. Read how Google uses information from sites that use its services.

Cookies and device storage

The site stores your measurement choice and your request drafts in this browser. Drafts, saved attachments and submitted copies remain in your device request history until you delete them or browser storage is cleared or evicted; starting another request does not delete the earlier one. If you allow measurement, a successful submission also creates a one-session receipt that prevents the same browser handoff from being counted twice and a private one-session proof that lets the submitting tab apply a later withdrawal to that exact saved enquiry. The proof is sent only in an authorization header to this site, never to analytics, and is kept in browser session storage. No analytics receipt or measurement-withdrawal proof is stored when you choose “Essential only.” If you allow measurement, Google Analytics and PostHog may set first-party measurement cookies or equivalent first-party identifiers. You can change or withdraw that choice at any time through the “Cookie settings” control shown on every page; withdrawal stops PostHog recording, updates Google consent, clears local analytics session data, propagates the browser choice to other open tabs, and—when the private session proof is available—durably marks the exact submitted enquiry as denied so no future Google Ads or PostHog lifecycle export can start from it.

To show progress after a successful submission, we also keep its private status link in browser session storage and temporary page memory, including when you choose “Essential only.” This essential service receipt contains the brief identifier and a status-access key, not your name, email or answers; it is not sent to analytics or kept in local storage. Withdrawing measurement consent does not remove it or interrupt your requested service.

After a brief is successfully saved with measurement consent, this site also sets or renews __Host-og-analytics-browser, a first-party cookie containing a random, server-signed pseudonymous browser identifier. It lasts for 90 days from that successful submission and can link later consented submissions from the same browser while it remains valid. It is not set for an “Essential only” submission. This identifier is saved with the enquiry's measurement-consent record; it is not a login, an email identity, or proof that the same person is using another browser or device. Withdrawing measurement consent sends a request to this site to remove the cookie. If that request cannot reach the server, “Cookie settings” asks you to retry; measurement in the browser stops immediately.

With measurement consent, local browser storage also keeps up to 20 receipt mappings between submitted brief identifiers and the random browser identifier. They contain no names, email addresses, form answers or private access keys. Unlike the one-session receipts, this small mapping can remain between browser sessions; withdrawing measurement consent or clearing browser storage removes it.

Retention and private links

Each enquiry is assigned a retention deadline 30 days after submission. The active brief, evaluation and internal lead-quality records, review audits, any private proposal, generated assets, and the per-enquiry key for the encrypted Brevo brief mirror are scheduled for removal at that deadline unless you ask to continue the project discussion or longer retention is required for security or legal reasons. Deleting that random key makes any longer-lived provider ciphertext unreadable. You may request earlier deletion at any time.

The private proposal URL contains a long, opaque access key. It is excluded from search indexing, but it acts as a bearer key rather than an account login: anyone who receives the full link may be able to open the proposal while it remains active. Do not forward it beyond the intended decision group.

Google Analytics and PostHog event-level data are intended to expire after no more than 14 months, and PostHog session recordings after no more than 30 days. These limits must also be enforced in the verified Outcome Guild provider projects before measurement is activated. Transactional email, contact-delivery records, provider security logs, and limited backups may remain under the relevant provider’s account settings or legal requirements after the active proposal is removed.

International processing

The service is intended for clients in the United States and other supported markets. Providers may process data in more than one country using the transfer safeguards described in their privacy terms.

Your choices

You may request access, correction, deletion, restriction, or withdrawal of consent by email. Withdrawing consent does not affect processing already completed. You may also contact the relevant data-protection authority for your location.

Sensitive information

Do not submit passwords, classified information, export-controlled technical data, health data, payment-card details, or other highly sensitive information through the public brief.

Effective 8 September 2026. This notice will be updated when the data flow or providers materially change.